PatchSiren

Duplicate Post CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Duplicate Post CVE published 2026-08-10

CVE-2026-19077

The Duplicate Post WordPress plugin before 1.5.5 is vulnerable to arbitrary post deletion due to a lack of per-object authorization checks in bulk copy and delete operations. This vulnerability allows any user with granted access to the plugin to permanently delete posts, including those belonging to other users. The CVE record was published on 2026-08-10T07:16:51.377Z and has not been modified since then [truncated]